I am confused after a lot of reading, I think that I have understood less than before!
I have my passport configured on Laravel 8:
'api' => [
'driver' => 'passport',
'provider' => 'users',
],
So I am serving via these routes: login, logout and registration.
Route::post('/register', [AuthController::class, 'register']);
Route::post('/login', [AuthController::class, 'login']);
Route::post('/logout', [AuthController::class, 'logout']);
And the AuthController provides the methods and almost works!
My questions are:
- If I add a guard to
logoutthis will not work. So is it unnecessary or am I with wrong logic? Or is it correct as I've written? - Do I need to manage
refresh tokens? And if yes, should the route be guarded? Or what have I to do when the token expires?
I have tried to add a method:
public function refresh() {
return $this->createNewToken(auth()->refresh());
}
But this gives me back this error:
BadMethodCallException: Method Illuminate\Auth\RequestGuard::refresh does not exist. in file /home/natty/workspace/sportIndexBackEnd/vendor/laravel/framework/src/Illuminate/Macroable/Traits/Macroable.php on line 103